Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
91

Gentoo GLSA-201502-09: Normal Severity Antiword Buffer Overflow Threat

A buffer overflow vulnerability in Antiword could result in execution of arbitrary code or Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201502-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Antiword: User-assisted execution of arbitrary code Date: February 07, 2015 Bugs: #531404 ID: 201502-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A buffer overflow vulnerability in Antiword could result in execution of arbitrary code or Denial of Service. Background ========= Antiword is a free MS Word reader. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-text/antiword < 0.37-r1 > = 0.37-r1 Description ========== A buffer overflow vulnerability has been found in wordole.c in Antiword. Impact ===== A remote attacker could entice a user to open a specially crafted document using Antiword, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Antiword users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-text/antiword-0.37-r1" References ========= [ 1 ] CVE-2014-8123 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8123 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201502-09 Concerns? ======== Security isa primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo GLSA 202301-14: Mitigating vulnerabilities in Zlib's compression algorithms to enhance defenses against potential exploitations in data handling.. Antiword Security Advisory, Gentoo Buffer Overflow, Denial of Service Fix. . LinuxSecurity.com Team

Calendar 2 Feb 07, 2015 Gentoo
198

Arch Linux ASA-201412-5 High: Antiword Buffer Overflow Risk

The package antiword before version 0.37-5 is suffering from a buffer overflow vulnerability that may lead to arbitrary code execution. . Arch Linux Security Advisory ASA-201412-5 ======================================== Severity: High Date : 2014-12-04 CVE-ID : CVE-2014-8123 Package : antiword Type : buffer overflow Remote : No Link : https://wiki.archlinux.org/title/CVE-2014 Summary ====== The package antiword before version 0.37-5 is suffering from a buffer overflow vulnerability that may lead to arbitrary code execution. Resolution ========= Upgrade to 0.37-5. # pacman -Syu "antiword> =0.37-5" The problem has not yet been fixed upstream but a local patch is applied. Workaround ========= None. Description ========== The program antiword is suffering from a buffer overflow within atPPSlist[].szName[] that may lead to denial of service or arbitrary code execution. Impact ===== An attacker is able to craft a special file hat triggers the buffer overflow leading to denial of service or arbitrary code execution. References ========= https://seclists.org/oss-sec/2014/q4/874 https://access.redhat.com/security/cve/CVE-2014-8123 https://bugs.archlinux.org/task/42982 . Arch Linux Security Advisory ASA-201412-5 ======================================== Severity: High Da. package, antiword, version, suffering, buffer, overflow, vulnerability. . LinuxSecurity.com Team

Calendar 2 Dec 05, 2014 ArchLinux
87

Debian 3.0: DSA 945-1 Critical: Antiword Insecure File Creation

Javier Fern�ndez-Sanguino Pe�a from the Debian Security Audit project discovered that two scripts in antiword, utilities to convert Word files to text and Postscript, create a temporary file in an insecure fashion.. - --------------------------------------------------------------------------Debian Security Advisory DSA 945-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze January 17th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : antiword Vulnerability : insecure temporary file Problem type : local Debian-specific: no CVE ID : CVE-2005-3126 Javier Fern�ndez-Sanguino Pe�a from the Debian Security Audit project discovered that two scripts in antiword, utilities to convert Word files to text and Postscript, create a temporary file in an insecure fashion. For the old stable distribution (woody) these problems have been fixed in version 0.32-2woody0. For the stable distribution (sarge) these problems have been fixed in version 0.35-2sarge1. For the unstable distribution (sid) these problems have been fixed in version 0.35-2. We recommend that you upgrade your antiword package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 571 d01edffc36adede5a946ece9cc2e7b8a Size/MD5 checksum: 7522 2054b50ce75109f2c8c659871a68282a Size/MD5 checksum: 193652 35e691b8b2b43abdffcd10cc50fa57ea Alpha architecture: Size/MD5 checksum: 107238 a0ebbfe56abc2e8f4b72afb1a86a2f6b ARM architecture: Size/MD5 checksum: 90428 b85f86c96e830021728ca3aa0782e9ac Intel IA-32 architecture: Size/MD5 checksum: 88702 7a22e5e6269d57f0668b99d14de613e0 Intel IA-64 architecture: Size/MD5 checksum: 119528 538882a3a023de9412c64956516b340c HP Precision architecture: Size/MD5 checksum: 100448 38a568c70a4b692980be5eb03d809fed Motorola 680x0 architecture: Size/MD5 checksum: 85460 0d937a7f5d960066a141cd3cd557e76c Big endian MIPS architecture: Size/MD5 checksum: 97980 4b7fdbb497be4c4e27e33c4d01b03b8f Little endian MIPS architecture: Size/MD5 checksum: 98020 a24cc132951b3a2b12fe9908aea0aff8 PowerPC architecture: Size/MD5 checksum: 93508 2b84fa8405f3a2a24e00c5502a81055c IBM S/390 architecture: Size/MD5 checksum: 91222 6f45812dff5c9bc0723d5b36132506cf Sun Sparc architecture: Size/MD5 checksum: 93016 3eb2f7bd4c423a0631b13ead57642543 Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 571 7b00ba3c9f119ea0aac47fe50e8244f4 Size/MD5 checksum: 7418 0e4ac21076325249672bbfa555b4d7d7 Size/MD5 checksum: 272236 eef3cc56105af2ef5cbd7cfce2e3f1a1 Alpha architecture: Size/MD5 checksum: 151336 99ccbf3f542b34b8b75e5a37c4512a4b AMD64 architecture: Size/MD5 checksum: 129418 57084beed85965f91493fec422dda213 ARM architecture: Size/MD5 checksum: 121580 0a5989999744cf71d3d96a06d1398535 Intel IA-32 architecture: Size/MD5 checksum: 119058 716405e114f0acf30ffd95cad83105ae Intel IA-64 architecture: Size/MD5 checksum: 161672 b0be0a3a6578a30abf87ce100966ffa1 HP Precisionarchitecture: Size/MD5 checksum: 132364 cd788ec85d29cd8d3dc632a5b2a32275 Motorola 680x0 architecture: Size/MD5 checksum: 112922 0becc709a718afbf8cffafb7cc439a40 Big endian MIPS architecture: Size/MD5 checksum: 135902 d44b070267c6b99c97f2c87477fe4475 Little endian MIPS architecture: Size/MD5 checksum: 135856 9d5af8fdf2ade7ed276002b67f59dc30 PowerPC architecture: Size/MD5 checksum: 127988 27e016d7e5055c4962cedd05db20d81c IBM S/390 architecture: Size/MD5 checksum: 131080 b072c4fa1585504147282375edd7c0ed Sun Sparc architecture: Size/MD5 checksum: 121718 77913c24afb10e98b542a9e5b18cdc52 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Notice DSA 946-1 addresses vulnerabilities in the ghostscript package related to improper file handling.. Insecure File Creation, Antiword Security Issue, Debian Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 27, 2006 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here